[ubuntu/noble-security] containerd-app 2.2.1-0ubuntu1~24.04.3 (Accepted)
Eduardo Barretto
eduardo.barretto at canonical.com
Thu Jun 25 11:09:44 UTC 2026
containerd-app (2.2.1-0ubuntu1~24.04.3) noble-security; urgency=high
* SECURITY UPDATE: HTTP/2 SETTINGS frame infinite loop (vendored
golang.org/x/net)
- debian/patches/CVE-2026-33814.patch: move s.Valid() check before
switch in ForeachSetting callback
- CVE-2026-33814
* SECURITY UPDATE: Uncontrolled Resource Consumption via unbounded
group parsing
- debian/patches/CVE-2026-47262.patch: bound user-database file
reads in openUserFile, reject non-regular files
- CVE-2026-47262
* SECURITY UPDATE: Insufficient Verification of Data Authenticity in
CRI checkpoint import
- debian/patches/CVE-2026-50195.patch: remove re-tagging of restored
checkpoint base images
- CVE-2026-50195
* SECURITY UPDATE: Reserved label propagation from image configs
- debian/patches/CVE-2026-53488.patch: filter containerd.io/ and
io.cri-containerd labels from image config
- CVE-2026-53488
* SECURITY UPDATE: UNIX Symbolic Link Following in CRI checkpoint
restore
- debian/patches/CVE-2026-53489.patch: add copyNoFollow,
checkpointArchiveEntryAllowed, assertCheckpointDirSafe; use
dedicated restore subdirectory
- CVE-2026-53489
* SECURITY UPDATE: Improper Input Validation of CDI annotations in
checkpoint restore
- debian/patches/CVE-2026-53492.patch: filter cdi.k8s.io
annotations on checkpoint restore
- CVE-2026-53492
containerd-app (2.2.1-0ubuntu1~24.04.2) noble; urgency=medium
* d/t/basic-smoke: use systemctl to start the service (LP: #2118738)
containerd-app (2.2.1-0ubuntu1~24.04.1) noble; urgency=medium
* New upstream version 2.2.1 (LP: #2127661)
* d/containerd.docs: update notice file
* d/copyright: update copyright data
* d/rules: fix path of containerd commands
* d/p/0001-Skip-test-failing-on-riscv64.patch: refresh patch
* d/p/0002-Skip-tests-*-privileg.patch: refresh patch
containerd-app (1.7.30-0ubuntu1~24.04.1) noble; urgency=medium
* New upstream version 1.7.30
* d/p/0001-Skip-test-failing-on-riscv64.patch: refresh patch
* d/p/CVE-2024-25621.patch: drop patch applied upstream
* d/p/CVE-2025-64329.patch: drop patch applied upstream
* d/control: build with golang 1.24
* d/rules: add golang 1.24 to PATH
* d/copyright: update copyright data
Date: 2026-06-24 06:59:12.092285+00:00
Changed-By: Eduardo Barretto <eduardo.barretto at canonical.com>
https://launchpad.net/ubuntu/+source/containerd-app/2.2.1-0ubuntu1~24.04.3
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list